PatchSiren cyber security CVE debrief
CVE-2026-71047 Oracle CVE debrief
A vulnerability in Oracle Identity Manager allows low-privileged attackers with network access via HTTP to compromise the product, potentially leading to takeover. Oracle has released an advisory and NVD has analyzed the vulnerability. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Identity Manager. Defenders should assess their exposure and apply patches or mitigations as necessary. The vulnerability has a high CVSS score of 8.8, indicating a high severity. The CVE record and NVD analysis provide details on the vulnerability, its impacts, and affected versions.
- Vendor
- Oracle
- Product
- Identity Manager
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-22
Who should care
Defenders of Oracle Identity Manager instances, particularly those with network exposure, should assess their exposure and apply patches or mitigations as necessary. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0 of Oracle Identity Manager. The vulnerability has a high CVSS score of 8.8, indicating a high severity. Defenders should verify their instances and apply patches or mitigations as necessary to prevent potential takeover.
Why it matters
Defenders should care about CVE-2026-71047 because it allows low-privileged attackers to potentially take over Oracle Identity Manager instances, impacting confidentiality, integrity, and availability. Affected versions require verification and patching.
- Potential takeover of Oracle Identity Manager instances
- Compromise of confidentiality, integrity, and availability
Technical summary
The vulnerability in Oracle Identity Manager (component: Core) allows low-privileged attackers with network access via HTTP to compromise the product. Successful attacks can result in takeover. Affected versions are 12.2.1.4.0 and 14.1.2.1.0. The vulnerability has a high CVSS score of 8.8, indicating a high severity. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The vulnerability is easily exploitable and allows low-privileged attackers to compromise Oracle Identity Manager, potentially leading to takeover.
Defensive priority
High
Recommended defensive actions
- Review and apply Oracle's security advisory
- Assess exposure of Oracle Identity Manager instances
- Verify version and apply patches if necessary
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD analysis provide details on the vulnerability, its impacts, and affected versions. The vulnerability is caused by a weakness in the Core component of Oracle Identity Manager. The CVE record was published on 2026-09-15T20:17:42.230Z and has not been modified since then. The NVD entry is currently Analyzed. The vulnerability allows low-privileged attackers with network access via HTTP to compromise Oracle Identity Manager, potentially leading to takeover. The affected versions are 12.2.1.4.0 and 14.1.2.1.0. The CV
Sources and references
Verified primary and authoritative sources
-
CVE-2026-71047 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-71047
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-71047 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-71047
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspusep2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.